 |
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.
|
11-09-2009
|
#1 | | |
New trojan Hi, there's this new trojan which I found on a website.
Its filename is Bookmark.exe.
Strange is that only 22/40 anti malware engines were able to detect it.
Currently, I was trying Norton 360 beta 4 which has failed to detect it. 
So far, this trojan has changed my IE8 homepage. Not sure what else it will do.
Here's the Virustotal link about the file analysis : Virustotal. MD5: edc631287a36a3b91990ec4f90fd7dc2 Trojan.Pasta.dyq Generic.Malware.sp!.20613D67 Generic.Malware.sp!.20613D67
Edit: I ran a quick scan from Vipre AV and it has detected everything of this trojan.
Also, this trojan tried to execute itself and Vipre deteted it.
Last edited by Dinesh; 11-09-2009 at 02:42 PM..
Reason: added info
| My System Specs | | System Manufacturer/Model Number Compaq OS Windows 7 Ultimate x64 CPU Intel core 2 duo T 5550 @ 1.83 GHz Motherboard Intel 965 express mobile chipset Memory 3 GB DR 2 @ 667 MHz Graphics Card Onboard with approx 512 MB RAM Sound Card Onboard Monitor(s) Displays 15"4 inch widescreen Hard Drives 160 GB SATA WD. Internet Speed sucks System Manufacturer/Model Number Compaq OS Windows 7 Ultimate x64 CPU Intel core 2 duo T 5550 @ 1.83 GHz Motherboard Intel 965 express mobile chipset Memory 3 GB DR 2 @ 667 MHz Graphics Card Onboard with approx 512 MB RAM Sound Card Onboard Monitor(s) Displays 15"4 inch widescreen Hard Drives 160 GB SATA WD. Internet Speed sucks |
11-09-2009
|
#4 | | W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi |
Hi there
How about publishing the website so this can either be Blacklisted or checked with other programs (or both) or even better to see if one's own computer is resistant against the infection.
Publishing that trojan xxxx can or cannot be detected isn't of any use to man or beast unless you can give some indications as to where and how the infection arose.
Some of the analyses on the Security forum are just like asking the question "How long is a piece of String".
Cheers
jimbo | My System Specs | | System Manufacturer/Model Number Custom built OS W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi CPU Q9400 QUAD Motherboard P5QL-CM Memory 8GB Graphics Card On Motherborad Sound Card Realtek HD audio Monitor(s) Displays Apple Cinema display Mouse Toshiba wireless laser Hard Drives 4 X 1TB SATA Internet Speed > 20MB up |
11-09-2009
|
#5 | | Windows 7 Ultimate 64 Bit |
Dinesh,
Have you tried detecting it with MSE? | My System Specs | | System Manufacturer/Model Number HP DV7-1170us OS Windows 7 Ultimate 64 Bit CPU Processor Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz, Motherboard Compal Keyboard IBM Enhanced Keyboard Mouse Synaptics PS/2 Touchpad |
11-09-2009
|
#6 | | Windows 7 Ultimate x64 + x86 + Windows 8 x64 |
Jimbo, Dinesh,
I would prefer if this was not posted in the open - no problem to send it via a PM but things in the open could cause problems to less experienced users | My System Specs | | System Manufacturer/Model Number Real World Computing (Me + a little help from Acer) OS Windows 7 Ultimate x64 + x86 + Windows 8 x64 CPU AMD Phenom II X6 1035T 2.6 GHz Motherboard Aspire M3400 Memory 4Gb PC10600 DDR3 1333 MHz Graphics Card NVIDIA GeForce 315 512MB Sound Card OnBoard - Realtek High Definition Audio Monitor(s) Displays Philips 32" HDTV, (HDMI) + 26" TV (VGA) Screen Resolution 1920 x 1080 @60Hz + 1360 x 768 @60Hz Keyboard Microsoft Wireless 800 or Stock Acer, (depends where I sit) Mouse Microsoft Wireless 800 or Stock Acer, (depends where I sit) PSU Stock (400W) Case Acer M3400 Cooling Stock Hard Drives 500 GB Seagate ST3500418AS SATA II
1 TB Hitachi HDS5C1010CLA382 SATAII
1 TB Samsung Spinpoint F1 HD103SI SATA II (external)
Plus various other (client ) HDDs as needed Internet Speed Temporaray 3G Dongle Other Info USB Capture + Webcam(s)
Also run Acer AspireOne 530h Netbook, Dual Core Atom + 1GB (Win7 Ult x86) |
11-10-2009
|
#7 | | |

Quote: Originally Posted by Barman58 Jimbo, Dinesh,
I would prefer if this was not posted in the open - no problem to send it via a PM but things in the open could cause problems to less experienced users  I agree hence i didnt post the link in the forum.
@richfrogg:
I have tried scanning it with MSE and it didnt detect it. | My System Specs | | System Manufacturer/Model Number Compaq OS Windows 7 Ultimate x64 CPU Intel core 2 duo T 5550 @ 1.83 GHz Motherboard Intel 965 express mobile chipset Memory 3 GB DR 2 @ 667 MHz Graphics Card Onboard with approx 512 MB RAM Sound Card Onboard Monitor(s) Displays 15"4 inch widescreen Hard Drives 160 GB SATA WD. Internet Speed sucks |
11-10-2009
|
#8 | | Windows 7 Ultimate x64 Service Pack 1 (Build 6.1.7601) |
No Anti-Virus software out there is 100% full proof no matter what they say, its just to with sales.
Its just a endless cycle that will never end. | My System Specs | | OS Windows 7 Ultimate x64 Service Pack 1 (Build 6.1.7601) CPU Intel Core 2 Quad Q6600 (G0 Kentsfield) LGA775 (FC-LGA6) Motherboard GIGABYTE GA-EP35C-DS3R (Rev. 2.1) Memory Corsair TW3X4G1333C9A 4GB PC-10600 (2x XMS3 2GB) Graphics Card ASUS nVIDIA GeForce 560 Sound Card RealTek ALC885/889A/890 Monitor(s) Displays ChiMei CMV CT-730D 17inch (LCD Monitor) Screen Resolution 1280-1024 60Hertz (Ture Colour 32bit) Keyboard Labtec Media Desktop Y-SAD65 Mouse Razer DeathAdder 3G Infrared Sensor (1800DPI) PSU ANTEC 750w Earthwatts Case Thermaltake Shark (VA7000SWA ATX) Full Tower Cooling Front 120mm fan (1400 RPM) /Rear 120mm (1400 RPM) blue LED Hard Drives 2x Barracuda 7200.10 SATA 3.0Gb/s 160-GB Hard Drive ST3160815AS (AHCI) Internet Speed Telstra BigPond Elite Liberty ADSL2+ 24Mbps/256kbps Other Info ASUS PCE-N13 802.11n Wireless LAN card |
11-10-2009
|
#9 | | Windows 7 Enterprise x64 SP1 |

Quote: Originally Posted by Barman58 Jimbo, Dinesh,
I would prefer if this was not posted in the open - no problem to send it via a PM but things in the open could cause problems to less experienced users 
Just to make this completely clear - ANYBODY that posts a link to any form of Virus/malware will get an instant life ban on all our sites.
Where viruses etc are concerned we have a zero tolerance policy. | My System Specs | | System Manufacturer/Model Number z3r010 OS Windows 7 Enterprise x64 SP1 CPU Intel i7 965 Extreme Edition Motherboard ASUS Rampage II Extreme Memory 12GB Corsair Dominator DDR3, PC3-12800 (1600) Graphics Card ATI HD5870 2GB Eyefinity 6 Sound Card SupremeFX X-Fi Monitor(s) Displays 3 x27" Dell & 3 x 23" Dell Screen Resolution 3 @ 2560x1440 & 3 @ 1920x1080 Keyboard Microsoft Ergononic 7000 Mouse Logitech Performance MX PSU 1200W Gigabyte ODIN Pro V2 PSU Case Thermaltake Tai Chi Cooling Corsair Hydro H50 Hard Drives RevoDrive Hybrid - 1TB
Intel X25-M SSD - 160GB Internet Speed 34 Mb/s ADSL2+ (Bonded) Other Info WinTV NovaTD
HP CP1515n Color Laser
Sony BD-5300S-0B Blu-ray Writer
Microsoft LifeCam Cinema
APC 750i Smart UPS |
11-10-2009
|
#10 | | Windows 7 Ultimate 32bit SP1 |
This has now been re-named to Trojan.StartPage.SSSPP ... This is a 'start page' hijacking.
URL's are changed all the time so this infection could be just about anywhere the site owner doesn't keep up with good surveillance and security. | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Other Info ATI HDMI Audio All times are GMT -5. The time now is 01:29 AM. |  |